Give your AI assistant a Hyperliquid wallet, not your key.

locker-mcp gives Claude Code, Cursor, Codex, Gemini CLI and any MCP client 42 tools. Every order goes through the same quote, limits and refusals as the lpa command.

Last updated: 4 October 2026

Add it to your assistant

The one-line installer puts locker-mcp beside lpa, on the same version. Claude Code takes it in one line. Claude Desktop, Cursor and Antigravity take the same JSON. Codex reads it from its TOML file, and Gemini CLI installs it as an extension.

Claude Code
claude mcp add locker -- ~/.lpa/bin/locker-mcp
Claude Desktop, Cursor, Antigravity
{  "mcpServers": {    "locker": { "command": "npx", "args": ["-y", "--ignore-scripts",      "@locker-protocol/agent-wallet-mcp@2.0.0"] }  }}
Codex
[mcp_servers.locker]command = "npx"args = ["-y", "--ignore-scripts", "@locker-protocol/agent-wallet-mcp@2.0.0"]
Keep the versions equal

A guardian signs nothing for a program of another version: the order answers VERSION_MISMATCH. With npx, pin the version to what lpa --version says.

42 tools

GroupTools
Market dataperps_venues, perps_markets, perps_quote, perps_regime, perps_ranges
Account readsperps_positions, perps_balance, perps_orders, wallet_address, wallet_balances
Ordersperps_open, perps_close, perps_cancel, perps_modify
Movements of fundsperps_deposit, perps_withdraw, perps_transfer
Paper tradingpaper_init, paper_status, paper_on, paper_off, paper_record, paper_replay
Setup and recordsstatus, doctor, policy_show, journal
The mandatemandate_show, mandate_sign, mandate_revoke
hyperkeelhyperkeel_status, hyperkeel_brief, hyperkeel_leaders, hyperkeel_follows, hyperkeel_follow, hyperkeel_unfollow, hyperkeel_alerts
Copiescopy_start, copy_stop, copy_status, copy_resume
The pilotpilot_status

Every tool carries the MCP hints, so a client knows which calls to ask you about: orders and movements of funds are marked destructive, reads are marked read-only. The tools of the plugins you install are added to these.

What it does alone, and what waits for you

  1. The assistant asks for an order without confirming it. It gets the quote, the policy's verdict and a quote id. Nothing is signed.
  2. It shows you the quote.
  3. Once you agree, it sends the same order again with that quote id. The id lasts ten minutes, works once, and belongs to that account, market, side, size and leverage.

Deposits, withdrawals and transfers are never signed here: the tool answers the command for you to type, and your phone signs it. Setting up, unlocking and arming the pilot refuse to run without a person at a terminal.

Paper first

The paper account fills on Hyperliquid's real book with the real fees and needs no key: an assistant can read, quote and trade on paper the minute it is added. A real order needs the guardian you unlocked.

Text from outside is data

An answer that carries words chosen by someone else, a market name as its deployer wrote it or a message from the venue, comes marked as untrusted data. An assistant should read it as data, never as an instruction.

Plugins

A plugin adds commands and tools. It runs in a separate process that reads its own folder only: it cannot read your keys, your settings or your journal, and it signs nothing for your real account. It can reach the network, and the install screen says so.